The Senior Application Security Engineer will lead the development and implementation of a robust application security program.
This role involves working closely with development teams to embed security practices early in the software development lifecycle, ensuring vulnerabilities are identified and mitigated before production.
The engineer will provide guidance, mentorship, and training to engineers while driving continuous improvement in security processes and tooling.
The position offers the opportunity to influence architectural decisions, secure critical systems, and contribute to the protection of millions of endpoints globally.
The ideal candidate thrives in a fully remote environment, enjoys collaborating with cross-functional teams, and has a strong passion for making security an integral part of software development.
Key responsibilities include designing, evaluating, and implementing software security standards, collaborating with engineers, serving as a subject matter expert, leading secure development training, partnering with DevOps, driving adoption of security tools, managing the Vulnerability Disclosure Program, and implementing auditable application security programs.
Requirements:
Proven experience leading application security architecture and design reviews, particularly with Ruby on Rails.
Extensive background working with developers to enforce application security standards and practices.
Expertise in software vulnerability management, including triage, assessment, analysis, and remediation.
Experience securing CI/CD pipelines with strong security controls using both off-the-shelf and custom tooling.
Hands-on experience with security testing tools across SAST, DAST, SCA, and IaC functional areas.
Knowledge of threat modeling frameworks and secure development processes.
Familiarity with IaaS/PaaS cloud infrastructure, infrastructure as code, and software-oriented architectures.
Excellent communication and collaboration skills to guide teams and gain buy-in for security initiatives.
Bonus: Expertise in OS, agent, and memory security across macOS, Linux, and Windows, with a focus on sandboxing and system-level isolation techniques.
Benefits:
The position offers a 100% remote work environment with flexibility to work from anywhere in the U.S.
A competitive base salary of $140,000–$165,000 plus bonus and equity options is provided.
Employees receive generous paid time off, including vacation, sick time, and holidays.
The company offers 12 weeks of paid parental leave.
Comprehensive medical, dental, and vision insurance plans are included.
A 401(k) plan with a 5% contribution regardless of employee contribution is available.
Life and disability insurance coverage is provided.
Stock options are available for full-time employees.
A one-time $500 reimbursement for home office setup or upgrades is offered.
An annual education and professional development allowance is included.
Employees receive a $75 monthly digital reimbursement.
Access to coaching, personal, and professional growth resources via the BetterUp platform is provided.